What is our primary use case?
My main use case for IBM HashiCorp Security Lifecycle Management is that secrets are stored in different places or updated separately by different teams, and we needed a centralized and policy-driven approach that can make access more consistent, improve traceability, and support the automation team. The setup total cost over time presented a problem, and this was the solution. Overall, IBM HashiCorp Security Lifecycle Management has been useful in my main use case.
My team uses IBM HashiCorp Security Lifecycle Management to automate credential rotation and secret delivery by generating credentials when the application needs them and setting an expiry.
Some common workflows leveraged by my team with IBM HashiCorp Security Lifecycle Management include dynamic database credentials, automated TLS certificate issuance and renewal, and secrets management for Kubernetes workloads. IBM HashiCorp Security Lifecycle Management can generate temporary database credentials with an expiration time, issue short-lived certificates through its PKI secrets engine, and authenticate applications running in Kubernetes with configurations, aiming to reduce manual credential rotation and improve security across application deployments.
How has it helped my organization?
Regarding how IBM HashiCorp Security Lifecycle Management has positively impacted my organization, I can say that concerning the ROI, we could calculate it as we save 18 hours per month at a fully loaded labor cost of $3,500 per hour leading to an annual labor value of $75,000. With incremental annual product and operating costs at $50,000, the net annual benefit would reduce to $25,000, excluding one-time implementation costs, showing good improvements.
To elaborate on how these time savings have changed my team's workflow, we track the time spent on credential updates and application onboarding, troubleshooting before and after implementation, and incidents such as failed updates or access-related problems to increase time for developers.
Integrating IBM HashiCorp Security Lifecycle Management with Azure services, such as Azure Active Directory and Kubernetes, has improved our management of secrets and machine identities by securing application workloads through Azure services with IBM HashiCorp. Using Entra ID helps with identity authentication while Kubernetes integration allows applications running in containers to authenticate to Vault and retrieve their authorized certificates, thereby reducing hardcoded credentials, improving access control, and making secret management more consistent across deployments.
Operational efficiency benefits we have observed after adopting IBM HashiCorp Security Lifecycle Management along with Azure include saving time by automating credential creation, rotation, application onboarding, and manual secret updates. We have enabled ourselves to save about 8 to 10 hours per month for a small set of applications.
What is most valuable?
From my experience, one of the best features that IBM HashiCorp Security Lifecycle Management offers is that the entire lifecycle of IBM HashiCorp Security Lifecycle Management includes several capabilities such as the provision to store secrets and credentials, as well as handling credential lifecycle management, focusing on identity-based access, and supporting service networking and Vault Radar which helps us identify exposed secrets in Git repositories. Along with a CI/CD pipeline, it is straightforward and helps us authenticate and retrieve only the credentials required for the deployment step, and all these features have really helped us a lot.
In terms of the features such as identity-based access, credential management, and integration with CI/CD pipelines, credentials management has made the biggest difference for my team, especially since sometimes things go out of scope and tend to store some scripts.
Regarding the CI/CD pipeline, the pipeline can be authenticated and only a legitimate user or an authenticated user can do the deployment or build step, which reduces the need to hardcode secrets in repositories or scripts while still ensuring safe handling of tokens, clear permissions, expiry, renewable behavior, and overall protection against secrets in logs.
With respect to cloud platforms, IBM HashiCorp Security Lifecycle Management supports cloud and hybrid environments, but each integration requires the correct identity configuration, network access, permissions, and monitoring. One consistent policy IBM HashiCorp Security Lifecycle Management has followed helps reduce fragmented practices across teams but does not eliminate the need to design and test each cloud integration separately, resulting in a really good cloud solution platform overall.
In terms of IBM HashiCorp Security Lifecycle Management's fit within our Azure architecture, it integrates well with Azure Entra ID.
What needs improvement?
In terms of areas for improvement in IBM HashiCorp Security Lifecycle Management, I believe making application onboarding repeatable, improving troubleshooting guidance for policy and authentication failures, and providing clear cost forecasting as the service grows would be beneficial.
The reason for my eight rating is that there are areas IBM HashiCorp Security Lifecycle Management can improve, particularly regarding integration capabilities and customer support. There are certain improvements needed for support and recovery procedures, along with better and cleaner documentation and community resources being really useful.
In terms of improvements needed for IBM HashiCorp Security Lifecycle Management that have not been discussed, documentation and customer support are significant areas. I believe IBM HashiCorp Security Lifecycle Management has a good solution that is really useful.
For how long have I used the solution?
I have been using IBM HashiCorp Security Lifecycle Management for the past one year, which has been really helpful since all the security features that are very important are handled by IBM HashiCorp Security Lifecycle Management itself.
What do I think about the stability of the solution?
IBM HashiCorp Security Lifecycle Management is stable.
What do I think about the scalability of the solution?
Concerning its scalability, IBM HashiCorp Security Lifecycle Management offers high availability, allowing us to increase cluster resources as demand grows.
How are customer service and support?
Customer support for IBM HashiCorp Security Lifecycle Management is quite good, providing solid response quality, resolution times, and escalations. They genuinely care about their customers and deliver excellent technical support without delays. I would rate customer support an eight out of ten.
Which solution did I use previously and why did I switch?
We have not used any other solution prior; this is the first solution we have been utilizing.
How was the initial setup?
Regarding needed improvements or challenges faced, I found that implementation, particularly during the proof of concept phase, was straightforward. However, production implementation involved more steps for installation, requiring identity integration, policy design, network planning, audit logs, backup, governance, recovery mechanisms, and thorough testing of changes and new features with only one representative, which is quite a load. Balancing the workload would be safer by providing two to three people.
What was our ROI?
We have indeed seen a return on investment as we save 18 hours per month, ensure credentials have expiry times, and keep track of those times and necessary rotations to avoid affecting application operations. IBM HashiCorp Security Lifecycle Management has also streamlined our TLS certificate renewals significantly.
What's my experience with pricing, setup cost, and licensing?
In terms of pricing, setup cost, and licensing, there is not a universal price for IBM HashiCorp Security Lifecycle Management, as it depends on the specific components and deployment model chosen. Public pricing can be very useful for making initial estimates and purchasing decisions.
Which other solutions did I evaluate?
We did not evaluate any other options before choosing IBM HashiCorp Security Lifecycle Management.
What other advice do I have?
My advice for others looking into using IBM HashiCorp Security Lifecycle Management is that if they need to reduce manual efforts in automating credentials and ensuring certificates do not expire, while maintaining application operations, IBM HashiCorp Security Lifecycle Management is a reliable option with dependable pipelines, services, and integration.
Regarding IBM HashiCorp Security Lifecycle Management's AI capabilities in governance and security, I believe the data is well secured and governed under regional security and data breach policies, especially across India, US, and UK.
When it comes to accuracy and reliability of IBM HashiCorp Security Lifecycle Management's output, I find accuracy to be good but not very good. With respect to reliability, one can depend on it for very good features regarding application authentication and credential lifecycle management that have been provided for years.
IBM HashiCorp Security Lifecycle Management is deployed on the cloud in my organization, and we generally use Microsoft Azure as our cloud provider.
I would rate IBM HashiCorp Security Lifecycle Management an eight out of ten overall.